Kubernetes Calico networking: calicoctl reports "reset by peer" and "bird: BGP: Unexpected connect from unknown address"
Solution 1:
The issue was NATing applied on VPN TUN (layer 3). Calico doesn't support it (or I'm not familiar with NATed solutions available).
Solution: use routes instead of NAT